PROPAGATING SECURITY IDENTITY INFORMATION TO COMPONENTS OF A COMPOSITE APPLICATION
    3.
    发明申请
    PROPAGATING SECURITY IDENTITY INFORMATION TO COMPONENTS OF A COMPOSITE APPLICATION 有权
    将安全身份信息传播给复合应用程序的组件

    公开(公告)号:US20140109195A1

    公开(公告)日:2014-04-17

    申请号:US14106037

    申请日:2013-12-13

    CPC classification number: H04L63/08 G06F9/461 G06F21/44

    Abstract: Various methods and systems for propagating identity information in a composite application are presented. State data of a composite application, as executed for a particular entity, may be transferred to and stored by a computer-readable storage medium. The state data may include a portion of a set of subject information linked with the entity. A security attribute of the subject may not be present in the portion of the set of subject information in the state data transferred to the non-transitory computer-readable storage medium. After a period of time, such as an hour or a day, the state data of the composite application as executed for the entity may be retrieved and the security attribute of the set of subject information linked with the entity may be determined The composite application may then continue to be executed for the entity.

    Abstract translation: 提出了用于在复合应用中传播身份信息的各种方法和系统。 对于特定实体执行的复合应用的状态数据可以被传送到计算机可读存储介质并由计算机可读存储介质存储。 状态数据可以包括与该实体链接的一组主题信息的一部分。 在传送到非暂时计算机可读存储介质的状态数据中,被摄体的安全属性可能不存在于该组主题信息的部分中。 经过一段时间(例如一小时或一天),可以检索对该实体执行的复合应用的状态数据,并且可以确定与该实体链接的一组主题信息的安全属性。复合应用可以 然后继续为该实体执行。

    Proxy servers within computer subnetworks

    公开(公告)号:US10362059B2

    公开(公告)日:2019-07-23

    申请号:US14696186

    申请日:2015-04-24

    Abstract: Embodiments of the invention include techniques for processing messages transmitted between computer networks. In some embodiments, messages such as requests and responses for various types of web services, applications, and other web content may be transmitted between multiple computer networks. One or more intermediary devices or applications, such as a proxy server implemented within a physical or logical subnetwork, may receive, process, and transmit the messages between the communication endpoints. In some embodiments, a proxy server may be configured to operate within a subnetwork of an internal computer network, exposing various web applications and/or services of the internal computer network to external computer networks. Such a proxy server may select specific policies for processing messages based on various message characteristics and the current point in a predetermined processing flow for the message. After selecting the specific policies to be applied to the message, the proxy server may process the message in accordance with the policies and forward the message to its intended destination.

    PROXY SERVERS WITHIN COMPUTER SUBNETWORKS
    5.
    发明申请
    PROXY SERVERS WITHIN COMPUTER SUBNETWORKS 审中-公开
    PROXY SERVERS在计算机子网中

    公开(公告)号:US20160088022A1

    公开(公告)日:2016-03-24

    申请号:US14696186

    申请日:2015-04-24

    Abstract: Embodiments of the invention include techniques for processing messages transmitted between computer networks. In some embodiments, messages such as requests and responses for various types of web services, applications, and other web content may be transmitted between multiple computer networks. One or more intermediary devices or applications, such as a proxy server implemented within a physical or logical subnetwork, may receive, process, and transmit the messages between the communication endpoints. In some embodiments, a proxy server may be configured to operate within a subnetwork of an internal computer network, exposing various web applications and/or services of the internal computer network to external computer networks. Such a proxy server may select specific policies for processing messages based on various message characteristics and the current point in a predetermined processing flow for the message. After selecting the specific policies to be applied to the message, the proxy server may process the message in accordance with the policies and forward the message to its intended destination.

    Abstract translation: 本发明的实施例包括用于处理在计算机网络之间传送的消息的技术。 在一些实施例中,可以在多个计算机网络之间传送诸如针对各种类型的web服务,应用和其他web内容的请求和响应的消息。 一个或多个中间设备或应用,例如在物理或逻辑子网内实现的代理服务器,可以在通信端点之间接收,处理和发送消息。 在一些实施例中,代理服务器可以被配置为在内部计算机网络的子网内操作,将内部计算机网络的各种web应用和/或服务暴露给外部计算机网络。 这样的代理服务器可以基于消息的各种消息特征和预定处理流程中的当前点来选择用于处理消息的特定策略。 在选择要应用于消息的特定策略之后,代理服务器可以根据策略处理消息,并将消息转发到其预定目的地。

    IDENTIFYING COMPATIBLE WEB SERVICE POLICIES
    6.
    发明申请
    IDENTIFYING COMPATIBLE WEB SERVICE POLICIES 有权
    识别兼容的WEB服务政策

    公开(公告)号:US20140129706A1

    公开(公告)日:2014-05-08

    申请号:US14148400

    申请日:2014-01-06

    CPC classification number: H04L43/04 H04L12/66 H04L63/102 H04L67/02

    Abstract: Methods, systems, and devices are described for identifying compatible web service policies between a web service and a web service client. A first and second set of one or more identifiers linked to web service policies supported by the web service and web service client may be calculated, respectively. The sets of identifiers may be compared. Using the comparison, a number of common identifiers present in the first set of one or more identifiers linked to the web service policies supported by the web service and the second set of one or more identifiers linked to the web service policies supported by the web service client may be identified. Using the number of common identifiers, a web service policy of the web service compatible with a web service policy of the web service client may be identified.

    Abstract translation: 描述了用于识别Web服务和Web服务客户端之间的兼容Web服务策略的方法,系统和设备。 可以分别计算链接到由web服务和web服务客户端支持的web服务策略的一个或多个标识符的第一和第二集合。 可以比较标识符集合。 使用比较,存在于链接到由web服务支持的web服务策略的一个或多个标识符的第一组中的多个公共标识符以及链接到由web服务支持的web服务策略的一个或多个标识符的第二组 客户可能被识别。 使用公共标识符的数量,可以识别与web服务客户端的web服务策略兼容的web服务的web服务策略。

    Attaching web service policies to a group of policy subjects

    公开(公告)号:US10791145B2

    公开(公告)日:2020-09-29

    申请号:US15408760

    申请日:2017-01-18

    Abstract: In one set of embodiments, methods, systems, and apparatus are provided to attach one or more service policies to resources in an enterprise by receiving a first service policy, receiving a first policy attachment that identifies one or more policy attachment attributes of resources in the enterprise, and generate a first global policy attachment that references the first policy attachment and the first service policy. The method can include receiving a request to access a resource including an attribute that matches one of the policy attachment attributes. The method can include determining that the first service policy is an effective policy for the resource based on the matching resource attribute with the policy attachment attribute. The method can include controlling access to the resource responsive to the request using the effective policy.

    Dynamic identity switching
    10.
    发明授权

    公开(公告)号:US10135803B2

    公开(公告)日:2018-11-20

    申请号:US15299196

    申请日:2016-10-20

    Abstract: Techniques are disclosed for dynamically switching user identity when generating a web service request by receiving, at a client application, an invocation of a web service, the invocation associated with a first authenticated user identity of a first user, identifying a second user identity, verifying that a switch from the first user identity to the second user identity is permitted by switching rules, including the second user identity in a service request when the switch is permitted, and communicating the service request to the web service. The switching rules can include associations between initial user identities and permitted user identities. Verifying that a switch is permitted can include searching the associations for an entry having an initial user identity that matches the first authenticated user identity and a new user identity that matches the second user identity, wherein the switch is permitted when the entry is found.

Patent Agency Ranking